Silver Peak Systems, Inc. develops software-defined wide-area network (SD-WAN) solutions and orchestration platforms that consolidate network edge connectivity and management, a role that places its products in critical infrastructure and enterprise network paths. The vendor's vulnerability footprint concentrates across its Unity EdgeConnect SD-WAN product line—including associated firmware for appliance models such as the NX 1000 and NX 2000—and its Unity Orchestrator management platform. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Silver Peak Systems, Inc. over time
Of all the CVEs published by Silver Peak Systems, Inc. as a CNA, 0.0% affect products that Silver Peak Systems, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Silver Peak Systems, Inc., 0.0% are self-published by Silver Peak Systems, Inc. as a CNA.
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12146HIGH In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server u | Nov 5, 2020 | 8.8 | 34 | NO | NO |
CVE-2019-16102CRITICAL Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity. | Sep 8, 2019 | 9.8 | 30 | NO | NO |
CVE-2020-12145CRITICAL Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This makes it possible to log in to O | Nov 5, 2020 | 9.8 | 26 | NO | NO |
CVE-2019-16099HIGH Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file. | Sep 8, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-16103HIGH Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature. | Sep 8, 2019 | 7.2 | 24 | NO | NO |
CVE-2019-16100HIGH Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-side HTTP traffic from a single source. | Sep 8, 2019 | 7.5 | 24 | NO | NO |
CVE-2020-12147HIGH In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using | Nov 5, 2020 | 8.8 | 22 | NO | NO |
CVE-2019-16104MEDIUM Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO. | Sep 8, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-16101MEDIUM Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/ | Sep 8, 2019 | 5.3 | 20 | NO | NO |
CVE-2020-12149MEDIUM The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequen | Dec 11, 2020 | 6.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Silver Peak Systems, Inc..
Media articles that mention a CVE ID that affects a product developed by Silver Peak Systems, Inc. — matched by CVE ID, not by vendor name.